Bug#381265: missing htpasswd2 manpage

2006-08-03 Thread martin f krafft
Package: apache2-utils Version: 2.0.55-4 Severity: normal subject says it all. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft <[EMAIL PROTECTED]> : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you

apache2 NMU?

2006-08-03 Thread Steve Kemp
Hi all, I'm interested in performing an NMU of Apache2, to close the following bugs: #380182: CVE-2006-3747: off-by-one security problem in mod_rewrite #374160: apache2 does not build with apt-build #343467: [CVE-2005-3352] XSS issue in mod_imap #349416: FTBFS: apr_sendfile for the Hu

Bug#381376: CVE-2006-3918: Missing Expect header sanitation may lead to XSS vulnerabilities

2006-08-03 Thread Stefan Fritsch
Package: apache2 Version: 2.0.55-4 Severity: grave Tags: security Justification: user security hole CVE-2006-3918 reads: http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does no

Bug#381381: CVE-2006-3918: Missing Expect header sanitation may lead to XSS vulnerabilities

2006-08-03 Thread Stefan Fritsch
Package: apache Version: 1.3.34-2 Severity: grave Tags: security Justification: user security hole CVE-2006-3918 reads: http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does no